Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Warning: Unable to locate ipset utility, disabling ipset support
- *filter
- :INPUT DROP [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT DROP [0:0]
- :delegate_input - [0:0]
- :delegate_output - [0:0]
- :delegate_forward - [0:0]
- :reject - [0:0]
- :input_rule - [0:0]
- :output_rule - [0:0]
- :forwarding_rule - [0:0]
- :syn_flood - [0:0]
- :zone_lan_input - [0:0]
- :zone_lan_output - [0:0]
- :zone_lan_forward - [0:0]
- :zone_lan_src_ACCEPT - [0:0]
- :zone_lan_dest_ACCEPT - [0:0]
- :zone_lan_dest_REJECT - [0:0]
- :input_lan_rule - [0:0]
- :output_lan_rule - [0:0]
- :forwarding_lan_rule - [0:0]
- -A zone_lan_input -m comment --comment "user chain for lan input" -j input_lan_rule
- -A zone_lan_output -m comment --comment "user chain for lan output" -j output_lan_rule
- -A zone_lan_forward -m comment --comment "user chain for lan forwarding" -j forwarding_lan_rule
- :zone_wan_input - [0:0]
- :zone_wan_output - [0:0]
- :zone_wan_forward - [0:0]
- :zone_wan_src_REJECT - [0:0]
- :zone_wan_dest_ACCEPT - [0:0]
- :zone_wan_dest_REJECT - [0:0]
- :input_wan_rule - [0:0]
- :output_wan_rule - [0:0]
- :forwarding_wan_rule - [0:0]
- -A zone_wan_input -m comment --comment "user chain for wan input" -j input_wan_rule
- -A zone_wan_output -m comment --comment "user chain for wan output" -j output_wan_rule
- -A zone_wan_forward -m comment --comment "user chain for wan forwarding" -j forwarding_wan_rule
- -A INPUT -j delegate_input
- -A OUTPUT -j delegate_output
- -A FORWARD -j delegate_forward
- -A delegate_input -i lo -j ACCEPT
- -A delegate_output -o lo -j ACCEPT
- -A delegate_input -m comment --comment "user chain for input" -j input_rule
- -A delegate_output -m comment --comment "user chain for output" -j output_rule
- -A delegate_forward -m comment --comment "user chain for forwarding" -j forwarding_rule
- -A delegate_input -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A delegate_output -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A delegate_forward -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A syn_flood -p tcp --syn -m limit --limit 25/second --limit-burst 50 -j RETURN
- -A syn_flood -j DROP
- -A delegate_input -p tcp --syn -j syn_flood
- -A reject -p tcp -j REJECT --reject-with tcp-reset
- -A reject -j REJECT --reject-with port-unreach
- -A zone_wan_input -p 17 -s fe80::/10 -d fe80::/10 --sport 547 --dport 546 -m comment --comment "Allow-DHCPv6" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 128 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Input" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 129 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Input" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 1 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Input" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 2 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Input" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 3 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Input" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 4/0 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Input" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 4/1 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Input" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 133 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Input" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 135 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Input" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 134 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Input" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 136 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Input" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 128 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Forward" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 129 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Forward" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 1 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Forward" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 2 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Forward" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 3 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Forward" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 4/0 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Forward" -j ACCEPT
- -A zone_wan_input -p 58 --icmpv6-type 4/1 -m limit --limit 1000/second -m comment --comment "Allow-ICMPv6-Forward" -j ACCEPT
- -A zone_lan_forward -m comment --comment "forwarding lan->wan" -j zone_wan_dest_ACCEPT
- -A zone_lan_input -j zone_lan_src_ACCEPT
- -A zone_lan_forward -j zone_lan_dest_REJECT
- -A zone_lan_output -j zone_lan_dest_ACCEPT
- -A zone_lan_src_ACCEPT -i br-lan -j ACCEPT
- -A zone_lan_dest_ACCEPT -o br-lan -j ACCEPT
- -A zone_lan_dest_REJECT -o br-lan -j reject
- -A delegate_input -i br-lan -j zone_lan_input
- -A delegate_forward -i br-lan -j zone_lan_forward
- -A delegate_output -o br-lan -j zone_lan_output
- -A zone_wan_input -j zone_wan_src_REJECT
- -A zone_wan_forward -j zone_wan_dest_REJECT
- -A zone_wan_output -j zone_wan_dest_ACCEPT
- -A zone_wan_dest_ACCEPT -o 6in4-henet -j ACCEPT
- -A zone_wan_src_REJECT -i 6in4-henet -j reject
- -A zone_wan_dest_REJECT -o 6in4-henet -j reject
- -A delegate_input -i 6in4-henet -j zone_wan_input
- -A delegate_forward -i 6in4-henet -j zone_wan_forward
- -A delegate_output -o 6in4-henet -j zone_wan_output
- -A zone_wan_dest_ACCEPT -o eth1 -j ACCEPT
- -A zone_wan_src_REJECT -i eth1 -j reject
- -A zone_wan_dest_REJECT -o eth1 -j reject
- -A delegate_input -i eth1 -j zone_wan_input
- -A delegate_forward -i eth1 -j zone_wan_forward
- -A delegate_output -o eth1 -j zone_wan_output
- -A delegate_input -j reject
- -A delegate_output -j reject
- -A delegate_forward -j reject
- COMMIT
- *mangle
- :mssfix - [0:0]
- -A FORWARD -j mssfix
- -A mssfix -o 6in4-henet -p tcp --tcp-flags SYN,RST SYN -m comment --comment "wan (mtu_fix)" -j TCPMSS --clamp-mss-to-pmtu
- -A mssfix -o eth1 -p tcp --tcp-flags SYN,RST SYN -m comment --comment "wan (mtu_fix)" -j TCPMSS --clamp-mss-to-pmtu
- COMMIT
- *raw
- :notrack - [0:0]
- -A PREROUTING -j notrack
- COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement